๐งช Community โ Claude Code โ Claude Desktop Standalone โข Secops-pack
Secops Pack
Security Operations โ cross-vendor alert triage, containment playbooks, and incident timelines across your EDR/MDR/SIEM stack.
Installation
Install this plugin individually:
/plugin marketplace add wyre-technology/msp-claude-plugins --plugin secops-pack Or install all MSP plugins at once:
/plugin marketplace add wyre-technology/msp-claude-plugins Features
- Alert Severity Normalization
- Bec Response
- Containment Playbooks
Skills
This plugin provides 3 skills that teach Claude about Secops Pack:
| Skill | Description |
|---|---|
alert-severity-normalization | Use this skill when triaging security alerts, incidents, or findings that come from more than one connected EDR/MDR/SIEM vendor and a single, comparable severity ranking is needed. |
bec-response | Use this skill when Business Email Compromise (BEC) is suspected or confirmed for a client. |
containment-playbooks | Use this skill when a security incident has been confirmed or is highly suspected and immediate first-response containment steps are needed. |
Agents
This plugin provides 3 agents for autonomous task execution:
| Agent | Description |
|---|---|
incident-timeline-builder | Use this agent when a security incident needs to be reconstructed into a single chronological timeline suitable for a client-facing incident report, pulling every relevant event across every connected security, PSA, and documentation tool for the client and time window in question. |
overnight-alert-summarizer | Use this agent when a technician needs a morning read on everything that fired overnight across the connected EDR/MDR/SIEM stack, normalized into one ranked digest instead of five separate vendor consoles. |
tenant-exposure-ranker | Use this agent when the MSP needs a portfolio-wide read on which clients carry the most current security risk โ open critical findings, unpatched or uncontained threats, MFA coverage gaps, and stale EDR/agent coverage โ ranked so leadership or the security team can prioritize attention. |
Commands
Available slash commands:
| Command | Description |
|---|---|
/incident-report | Build a client-facing incident summary for a given client and time window, assembling a chronological timeline across every connected security, PSA, and documentation tool |
/portfolio-sweep | Sweep every connected security tool across all clients/tenants, normalize findings, and report the top most urgent items portfolio-wide |
/tenant-exposure | Run the exposure ranking for one client or the whole portfolio โ open critical findings, unmitigated threats, MFA gaps, and stale EDR coverage |
API Reference
| Base URL | |
| Authentication | |
| Rate Limit | |
| Documentation |
Example Usage
Build a client-facing incident summary for a given client and time window, assembling a chronological timeline across every connected security, PSA, and documentation tool
/incident-report Sweep every connected security tool across all clients/tenants, normalize findings, and report the top most urgent items portfolio-wide
/portfolio-sweep Run the exposure ranking for one client or the whole portfolio โ open critical findings, unmitigated threats, MFA gaps, and stale EDR coverage
/tenant-exposure Using Skills
/skill secops-pack:alert-severity-normalization
Use this skill when triaging security alerts, incidents, or findings that come from more than one connected EDR/MDR/SIEM vendor and a single, comparable severity ranking is needed.